I was looking at using your package, but when I read your code and compare it with the manual it says that you should not share the app_secret client side. It suggests you should use the client side implicit authentication. link
Are you aware of this? This looks like an issue that is resolvable. The implicit authentication does not need the secret.